
Wrong Password Security & Risk Analysis
wordpress.org/plugins/alex-wrong-passwordWhen someone gets a password wrong or uses the forgotten password form on your site, the administrator is emailed with the details that were entered.
Is Wrong Password Safe to Use in 2026?
Generally Safe
Score 85/100Wrong Password has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "alex-wrong-password" v9.0 plugin exhibits a strong security posture in several key areas. It has a clean vulnerability history with no recorded CVEs, suggesting a consistent focus on security from the developers. The absence of dangerous functions, file operations, and external HTTP requests is also a positive sign. Crucially, all SQL queries are prepared, mitigating the risk of SQL injection. However, there are significant concerns raised by the static analysis. The complete lack of output escaping for all identified outputs is a critical weakness, potentially exposing the site to Cross-Site Scripting (XSS) vulnerabilities. Furthermore, the taint analysis reveals two flows with unsanitized paths, which, although not classified as critical or high severity in this report, warrant investigation as they indicate potential pathways for attackers to inject malicious data. The absence of capability checks and nonce checks on any potential entry points, though the attack surface is reported as zero, leaves room for concern if future updates introduce such points without adequate protection.
Key Concerns
- All outputs are unescaped
- Taint analysis shows unsanitized paths
- No capability checks present
- No nonce checks present
Wrong Password Security Vulnerabilities
Wrong Password Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Wrong Password Attack Surface
WordPress Hooks 5
Maintenance & Trust
Wrong Password Maintenance & Trust
Maintenance Signals
Community Trust
Wrong Password Alternatives
WPS Hide Login
wps-hide-login
Change wp-login.php to anything you want.
Rename wp-login.php to anything you want
rename-wp-loginphp-to-anything-you-want
This plugin changes the way you login into your website.
Login Me Now – Passwordless, Magic Link, OTP & Social Login for WordPress
login-me-now
Login Me Now combines Passwordless Login, Email Magic Links, Phone OTP Verification, Temporary Logins, Social Logins (Google & Facebook), User Swi …
Blue Login Style
blue-login-style
Blue Login Style is a tiny plugin which allows to customize your wp-login theme easily with a click.
NoMorePass Login
nomorepass-forget-your-passwords
Use your mobile phone to login into wordpress. Allow users instant registration. Fully protection against force brute attacks
Wrong Password Developer Profile
6 plugins · 80 total installs
How We Detect Wrong Password
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
http://mrstats.strangebutfunny.net/statsscript.phpHTML / DOM Fingerprints
wrap